648 Configuring communication with RADIUS
NN47250-500 (Version 03.01)

Split authentication and authorization

It allows the RADIUS server to authenticate a user, but authorization attributes are taken from the WSS local user
database. This is accomplished by including a Vendor Specific Attribute (VSA) in the RADIUS Accept response. When
the WSS receives the RADIUS Accept response, the WSS uses the group name and attempts to match it to authorization
attributes of a corresponding user group in the local user database.
For the user-group name, specify a value consisting of a string 1-32 characters long. Additional values consist of the
following:
Type - 26
Vendor ID- 14525
Vendor Type - 9 (Nortel VSA)
Attributes that appear in the RADIUS Access Accept response are added to the session attributes. If the Access Accept
has a Nortel group-name VSA, the attributes from the corresponding user group in the local database are applied.